vendor:
Opera
by:
Ahmed Obied
9.3
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Opera
Affected Version From: 9.64
Affected Version To: 9.64
Patch Exists: YES
Related CWE: N/A
CPE: a:opera_software:opera
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2021
Opera 9.64 Remote Buffer Overflow Exploit
This exploit is similar to the bug found by Wojciech Pawlikowski for Firefox. It was tested using the latest version of Opera (9.64). The exploit is a GET request to the server which sends a header with a content type of text/xml and a payload of 7400 'A' characters. This causes a buffer overflow and can be used to execute arbitrary code.
Mitigation:
Update to the latest version of Opera.